The Numbers Are Stark — and Getting Worse
Almost two out of every three organizations hit by ransomware say artificial intelligence made the attack more effective. That’s the headline finding from a new global survey of cybersecurity professionals conducted by Proofpoint. The figure: 65%.
The 2026 AI-Era Ransomware Report, published July 22, doesn’t mince words. Across the incidents studied, AI involvement was the norm, not the exception. Attackers are no longer just using brute force or luck. They are leaning on AI to craft phishing emails, impersonate trusted contacts, and steal credentials at a scale and polish that was impossible just a few years ago.
This isn’t a futuristic warning. It’s happening now.
How AI Changes the Entry Point
Ransomware doesn’t start with encryption. It starts with a click. According to the report, human interaction remains the primary entry vector. Of the incidents analyzed:
- 47% involved a malicious link somewhere in the attack chain
- 46% used a malicious attachment
- 36% relied on credential harvesting
What’s changed is the quality of the lure. In the past, a phishing email might have clumsy phrasing, a mismatched logo, or a login page that felt off. Those small red flags gave employees a moment of pause. Not anymore.
Now, with AI tools, attackers can generate messages that look like legitimate business communications. No awkward grammar. No obvious tells. The report found that 40% of respondents said the initial lure appeared so legitimate that the employee simply didn’t suspect anything was wrong.
AI Doesn’t Reinvent Ransomware — It Supercharges It
Ryan Kalember, Proofpoint’s chief strategy officer, put it plainly: “AI hasn’t fundamentally changed ransomware, but it has materially improved the attacks that lead to ransomware.”
He added that today’s attackers use AI to create highly convincing phishing emails, generate malware components like scripts, and run credential theft campaigns that exploit human trust at scale. His warning to organizations: if you still treat ransomware as an endpoint or recovery problem, you’re missing what these attacks most frequently begin with — people, identities, and trusted communications.
Security Controls Are Failing, Too
It’s not just human judgment that’s failing. Enterprise software defenses are also struggling. A third of surveyed organizations said their existing email security controls failed to detect the attack entirely. Another quarter cited misconfigurations or outright gaps in their security controls.
That means even companies with up-to-date email gateways, endpoint detection, and training programs are getting caught off guard. The attackers are using AI to bypass technical controls as well as human ones.
Proofpoint’s recommendation is blunt: organizations that want to reduce ransomware risk must focus on stopping attacks at the point of entry, protecting identities from compromise, and responding before attackers can turn access into extortion.
What This Means for Your Organization
The takeaway isn’t that AI is unbeatable. It’s that the bar for what looks suspicious has moved. Old-school phishing indicators — bad grammar, weird logos — are no longer reliable. Attackers can now generate polished, personalized lures at scale.
That means security teams need to shift their focus. Instead of relying solely on employees to spot a bad email, they should invest in identity protection, stronger authentication, and faster response times. Because by the time the ransomware payload drops, the real damage — the access, the credential theft, the foothold — has already happened.
For more on why ransomware remains one of cybersecurity’s most persistent threats, read our deep dive on the evolving ransomware landscape.